Trend Micro has warned customers to immediately secure their systems against an actively exploited remote code execution vulnerability in its Apex One endpoint security platform. Apex One is an endpoint security platform designed to automatically detect and respond to threats, including malicious tools, malware, and vulnerabilities. This critical security flaw (tracked as CVE-2025-54948 and CVE-2025-54987 depending on the CPU architecture) is due to a command injection weakness in the Apex One Management Console (on-premise) that enables pre-authenticated attackers to execute arbitrary code remotely on systems running unpatched software. Trend Micro has yet to issue security updates to patch this actively exploited vulnerability, but it has released a mitigation tool that provides short-term mitigation against exploitation attempts. The Japanese CERT also issued an alert regarding the active exploitation of the two flaws, urging users to mitigate them as soon as possible. "While it will fully protect against known exploits, it will disable the ability for administrators to utilize the Remote Install Agent function to deploy agents from the Trend Micro Apex One Management Console," the company explained in a Tuesday advisory. "Trend Micro has observed as least one instance of an attempt to actively exploit one of these vulnerabilities in the wild." The company said it will release a patch around the middle of August 2025, which will also restore the Remote Install Agent funct...
Trend Micro warns of Apex One zero-day exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Aug 6, 2025
·Updated
Affected Software
1 affected component
Trend Micro Apex One
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in Trend Micro's Apex One endpoint security platform that is currently being exploited in attacks.
2
What security implications are discussed?
The article highlights the risk of remote code execution due to the zero-day vulnerability, which could allow attackers to gain control of affected systems.
3
What products or software are affected?
The affected software mentioned in the article is Trend Micro Apex One.
4
What actions should users take in response to this vulnerability?
Users are urged to immediately secure their systems by applying the necessary updates and patches provided by Trend Micro.
5
Is there any indication of when this vulnerability was discovered?
The article does not specify when the zero-day vulnerability was discovered, but it emphasizes its active exploitation in the wild.